Network Vulnerability Assessment via Dynamic Service Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for assessing network vulnerabilities in large enterprises with numerous computing devices spread across multiple IP address ranges or subnets are inefficient, as they struggle to keep track of devices, ensure regular port scanning, and effectively allocate resources for vulnerability assessments.

Innovation Solution

A computer-implemented method that determines addresses for target devices, assigns port scanning and vulnerability scanning tasks to associated services, and generates reports based on scanning results, employing a tiered scanning approach to optimize resource usage and identify anomalous results.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If systematic port scanning is performed on all computing devices using a static IP address list, then vulnerability assessment can be performed, but the system cannot scale when the enterprise has a large number of computing devices spread across multiple IP address ranges or subnets

Engineering Contradiction:
Improvevulnerability assessment capabilityVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the vulnerability assessment system into multiple independent components: IP address range management, device discovery services, port scanning services, and vulnerability assessment services. Each component operates independently and can be scaled separately, allowing the system to handle large numbers of devices across multiple subnets without becoming unmanageably complex.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a flat, static IP address list approach to a multi-dimensional dynamic system that includes IP address ranges, subnet information, device discovery mechanisms, and real-time device status tracking. This dimensional expansion enables the system to scale across multiple network segments while maintaining manageability through structured organization.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If comprehensive port scanning is performed on all computing devices, then all vulnerabilities can be identified, but resource consumption increases significantly

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidcomputing resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent implements partial action by performing port scanning only on devices that are currently active and within monitored IP address ranges, rather than scanning all devices in the enterprise. The system dynamically adjusts scanning scope based on device discovery results, reducing unnecessary resource consumption while maintaining comprehensive vulnerability assessment for relevant devices.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent performs preliminary device discovery and status verification before initiating port scanning. By first identifying active devices and their current IP addresses through discovery services, the system avoids wasting resources scanning inactive devices or devices outside the monitoring scope, thereby reducing overall resource consumption while maintaining detection accuracy for active devices.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If manual tracking of computing devices is performed, then device inventory can be maintained, but the system cannot keep track of devices being brought into service, removed from service, or assigned different IP addresses

Engineering Contradiction:
Improvedevice tracking accuracyVSAvoidoperational effort
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service through automated device discovery services that continuously monitor the network for active devices, automatically update IP address bindings, and notify the vulnerability assessment system of device status changes. This eliminates the need for manual tracking while maintaining high reliability in device inventory accuracy, as the system self-updates based on observed network activity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent establishes feedback loops where device discovery services continuously report device status changes to the central management system, which then adjusts the vulnerability assessment scope accordingly. This automated feedback mechanism ensures the system always has current information about active devices, IP address assignments, and service status without requiring manual intervention, thereby maintaining reliability while reducing operational effort.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11736507B2Techniques for analyzing network vulnerabilities
Publication Date: 2023.08.22 DISNEY ENTERPRISES INC
  • US11736507B2 patent drawing
  • US11736507B2 patent drawing
  • US11736507B2 patent drawing

AI summary

One embodiment of the present disclosure sets forth a technique for analyzing network vulnerabilities. The technique includes determining an address for each target device included in a plurality of target devices; for each target device, assigning a port scanning task to an associated port scanning service, the port scanning task being associated with the target device via the address of the target device; for each port scanning task, receiving a port scanning result from the port scanning service assigned to the port scanning task, the port scanning result including a list of open ports for the target device associated with the port scanning task; for each open port included in each port scanning result, assigning a vulnerability scanning task to an associated vulnerability service; receiving a vulnerability scanning result for each vulnerability scanning task; and generating a report based on the port scanning results or the vulnerability scanning results.